CVE-2025-20088 PUBLISHED CVSS 6.5 MEDIUM

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.

EPSS 0.45% · 63.3th percentile

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.45%
63.3th percentile

Affected Products

VendorProductVersions
mattermostmattermost_server10.0.0, 10.2.0, 10.1.0
MattermostMattermost10.1.4, 10.2.0, 9.11.0
github.commattermost/mattermost/server/v810.0.0, 10.2.0, 0

Timeline

References

Open in Interactive Console →